Written by
Dan Knauss
on
September 27, 2023
Last Updated on September 27, 2023
Since last week, 48 total vulnerabilities have emerged in public disclosure. They may affect over three million WordPress sites. There are 39 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are nine plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
WordPress Core Vulnerabilities — Patched
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.
Website Builder by SeedProd
Plugin Slugcoming-soon
Installations1,000,000+
VulnerabilityCross Site Request Forgery (CSRF)
Patched in Version6.15.15.3
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 6.15.15.3.
Ad Inserter
Plugin Slugad-inserter
Installations300,000+
VulnerabilitySensitive Data Exposure
Patched in Version2.7.31
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.7.31.
Ad Inserter
Plugin Slugad-inserter
Installations300,000+
VulnerabilitySensitive Data Exposure
Patched in Version2.7.31
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.7.31.
Table of Contents Plus
Plugin Slugtable-of-contents-plus
Installations300,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version2309
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2309.
WPvivid
Plugin Slugwpvivid-backuprestore
Installations300,000+
VulnerabilityArbitrary File Deletion
Patched in Version0.9.90
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 0.9.90.
WPvivid
Plugin Slugwpvivid-backuprestore
Installations300,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version0.9.90
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 0.9.90.
iframe
Plugin Slugiframe
Installations100,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version4.7
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 4.7.
wpDiscuz
Plugin Slugwpdiscuz
Installations80,000+
VulnerabilitySQL Injection
Patched in Version7.6.6
Severity ScoreCritical
The vulnerability has been patched, so you should update to version 7.6.6.
Media Library Assistant
Plugin Slugmedia-library-assistant
Installations70,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.11
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 3.11.
Connect Matomo (WP-Matomo, WP-Piwik)
Plugin Slugwp-piwik
Installations60,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.0.29
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.0.29.
Simple Membership
Plugin Slugsimple-membership
Installations50,000+
VulnerabilityPrivilege Escalation
Patched in Version4.3.5
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 4.3.5.
Simple Membership
Plugin Slugsimple-membership
Installations50,000+
VulnerabilityPrivilege Escalation
Patched in Version4.3.5
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 4.3.5.
Ditty
Plugin Slugditty-news-ticker
Installations40,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.1.25
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 3.1.25.
BEAR
Plugin Slugwoo-bulk-editor
Installations30,000+
VulnerabilityBroken Access Control
Patched in Version1.1.4
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.1.4.
BEAR
Plugin Slugwoo-bulk-editor
Installations30,000+
VulnerabilityCross Site Request Forgery (CSRF)
Patched in Version1.1.4
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.1.4.
Poptin
Plugin Slugpoptin
Installations20,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.3.1
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.3.1.
Copy Anything to Clipboard
Plugin Slugcopy-the-code
Installations10,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version2.6.5
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.6.5.
Statify
Plugin Slugextended-evaluation-for-statify
Installations10,000+
VulnerabilityCSV Injection
Patched in Version2.6.4
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.6.4.
Modal Window
Plugin Slugmodal-window
Installations10,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version5.3.6
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 5.3.6.
Options for Twenty Seventeen
Plugin Slugoptions-for-twenty-seventeen
Installations10,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version2.5.1
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.5.1.
WP Mailto Links
Plugin Slugwp-mailto-links
Installations10,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.1.4
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 3.1.4.
Widget Responsive for Youtube
Plugin Slugyoutube-widget-responsive
Installations10,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.6.2
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.6.2.
iPanorama 360 – WordPress Virtual Tour Builder
Plugin Slugipanorama-360-virtual-tour-builder-lite
Installations7,000+
VulnerabilitySQL Injection
Patched in Version1.8.0
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 1.8.0.
Drag and Drop Multiple File Upload
Plugin Slugdrag-and-drop-multiple-file-upload-for-woocommerce
Installations4,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.1.1
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 1.1.1.
DoLogin Security
Plugin Slugdologin
Installations3,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.7
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 3.7.
Import XML and RSS Feeds
Plugin Slugimport-xml-feed
Installations3,000+
VulnerabilityRemote Code Execution (RCE)
Patched in Version2.1.5
Severity ScoreCritical
The vulnerability has been patched, so you should update to version 2.1.5.
Import XML and RSS Feeds
Plugin Slugimport-xml-feed
Installations3,000+
VulnerabilityArbitrary File Upload
Patched in Version2.1.4
Severity ScoreCritical
The vulnerability has been patched, so you should update to version 2.1.4.
Pretty Google Calendar
Plugin Slugpretty-google-calendar
Installations2,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.6.0
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.6.0.
WPSchoolPress
Plugin Slugwpschoolpress
Installations2,000+
VulnerabilityCross Site Request Forgery (CSRF)
Patched in Version2.2.5
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.2.5.
Bit Assist
Plugin Slugbit-assist
Installations1,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.2
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.2.
Leaflet Map
Plugin Slugextensions-leaflet-map
Installations1,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.3.1
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 3.3.1.
Simple Posts Ticker
Plugin Slugsimple-posts-ticker
Installations1,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.1.6
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.1.6.
Simple Posts Ticker
Plugin Slugsimple-posts-ticker
Installations1,000+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.1.6
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.1.6.
Funnelforms Free
Plugin Slugfunnelforms-free
Installations800+
VulnerabilityCross Site Scripting (XSS)
Patched in Version3.4
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 3.4.
User Avatar – Reloaded
Plugin Sluguser-avatar-reloaded
Installations800+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.2.2
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.2.2.
Memberlite Shortcodes
Plugin Slugmemberlite-shortcodes
Installations700+
VulnerabilityCross Site Scripting (XSS)
Patched in Version1.3.9
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 1.3.9.
Serial Codes Generator and Validator with WooCommerce Support
Plugin Slugserial-codes-generator-and-validator
Installations600+
VulnerabilityCross Site Scripting (XSS)
Patched in Version2.4.15
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.4.15.
User Activity Log Pro
PluginUser Activity Log Pro
Plugin Sluguser-activity-log-pro
VulnerabilityCross Site Scripting (XSS)
Patched in Version2.3.4
Severity ScoreHigh
The vulnerability has been patched, so you should update to version 2.3.4.
User Activity Log Pro
PluginUser Activity Log Pro
Plugin Sluguser-activity-log-pro
VulnerabilityBypass Vulnerability
Patched in Version2.3.4
Severity ScoreMedium
The vulnerability has been patched, so you should update to version 2.3.4.
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Popup Builder
Plugin Slugpopup-builder
Installations200,000+
VulnerabilityCross Site Scripting (XSS)
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched. You should deactivate the plugin.
Active Directory Integration / LDAP Integration
Plugin Slugldap-login-for-intranet-sites
Installations5,000+
VulnerabilityBroken Access Control
Patched in VersionNo Fix
Severity ScoreLow
The vulnerability has not been patched. You should deactivate the plugin.
WP Job Portal
Plugin Slugwp-job-portal
Installations3,000+
VulnerabilitySQL Injection
Patched in VersionNo Fix
Severity ScoreCritical
The vulnerability has not been patched. You should deactivate the plugin.
Staff / Employee Business Directory for Active Directory
Plugin Slugldap-ad-staff-employee-directory-search
Installations10+
VulnerabilityBroken Access Control
Patched in VersionNo Fix
Severity ScoreLow
The vulnerability has not been patched. You should deactivate the plugin.
Easy Registration Forms
PluginEasy Registration Forms
Plugin Slugeasy-registration-forms
VulnerabilitySensitive Data Exposure
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Contact Form by FormGet
PluginFormGet Contact Form
Plugin Slugformget-contact-form
VulnerabilityCross Site Scripting (XSS)
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Super Store Finder
PluginSuper Store Finder
Plugin Slugsuperstorefinder-wp
VulnerabilityBroken Access Control
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched. You should deactivate the plugin.
Vrm 360 3D Model Viewer
PluginVrm 360 3D Model Viewer
Plugin Slugvrm360
VulnerabilitySensitive Data Exposure
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Charts
Pluginwp-charts
Plugin Slugwp-charts
VulnerabilityCross Site Scripting (XSS)
Patched in VersionNo Fix
Severity ScoreMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
WordPress Theme Vulnerabilities
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.
Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.
Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-09-27 09:32:11.
The article was hand-picked and curated for you by the Editorial Team of WP Archives.